Vulnerabilities > Cleartext Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2021-04-23 CVE-2021-31539 Cleartext Storage of Sensitive Information vulnerability in Wowza Streaming Engine
Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.password file.
local
low complexity
wowza CWE-312
5.5
2021-04-13 CVE-2021-3473 Cleartext Storage of Sensitive Information vulnerability in Lenovo Xclarity Controller
An internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/restore password may be written to an internal XCC log buffer if Lenovo XClarity Administrator (LXCA) is used to perform the backup/restore.
network
low complexity
lenovo CWE-312
4.9
2021-04-06 CVE-2021-25692 Cleartext Storage of Sensitive Information vulnerability in Teradici Pcoip Connection Manager and Security Gateway 20.07/21.01
Sensitive smart card data is logged in default INFO logs by Teradici's PCoIP Connection Manager and Security Gateway prior to version 21.01.3.
low complexity
teradici CWE-312
4.6
2021-04-02 CVE-2020-11924 Cleartext Storage of Sensitive Information vulnerability in Wizconnected Colors A60 Firmware 1.14.0
An issue was discovered in WiZ Colors A60 1.14.0.
local
low complexity
wizconnected CWE-312
5.5
2021-04-02 CVE-2020-11923 Cleartext Storage of Sensitive Information vulnerability in Wizconnected WIZ 1.14.0
An issue was discovered in WiZ Colors A60 1.14.0.
local
low complexity
wizconnected CWE-312
5.5
2021-03-30 CVE-2020-4944 Cleartext Storage of Sensitive Information vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2, stores keystore passwords in plain text after a manual edit, which can be read by a local user.
local
low complexity
ibm CWE-312
5.5
2021-03-30 CVE-2020-4884 Cleartext Storage of Sensitive Information vulnerability in IBM Urbancode Deploy 6.2.7.9/7.0.5.4/7.1.1.1
IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm CWE-312
5.5
2021-03-29 CVE-2021-28937 Cleartext Storage of Sensitive Information vulnerability in Acexy Wireless-N Wifi Repeater Firmware 28.08.06.1
The /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) contains the administrator account password in plaintext.
network
low complexity
acexy CWE-312
7.5
2021-03-26 CVE-2021-22194 Cleartext Storage of Sensitive Information vulnerability in Gitlab
In all versions of GitLab, marshalled session keys were being stored in Redis.
local
low complexity
gitlab CWE-312
4.4
2021-03-17 CVE-2020-35455 Cleartext Storage of Sensitive Information vulnerability in Taidii Diibear 2.4.0
The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from Shared Preferences and the SQLite database because of insecure data storage.
local
low complexity
taidii CWE-312
7.8